Case Studies

Our case studies

Concrete engagements, across every sector

From public sector to private, from mutual insurer to museum: every engagement combines architecture, cloud and cybersecurity. Out of respect for confidentiality, our references are presented by sector, without naming our clients.

Insurance & mutual insurers

Full overhaul and hardening of a mutual insurer's IT system

Migration of email and users to a hybrid Microsoft 365 cloud architecture, rebuilding of the IT system on a resilient multi-site vSphere platform with a business continuity plan, network segmentation through a next-generation firewall cluster, VPN access with MFA, Centreon/Wazuh monitoring, EDR with an outsourced SOC and immutable backups.

→ A modernised, resilient IT system, ready to meet insurance partners’ audits.

Reinsurance & finance

Full-cloud migration of a reinsurer's subsidiary

Carve-out of a subsidiary from a hybrid tenant to a cloud-native Azure / Microsoft 365 tenant: tenant-to-tenant migration of data (email, OneDrive, Teams, SharePoint), telephony switch-over to Teams Phone, industrialised workstation deployment via Intune and AutoPilot, hardening of the Azure and Defender environment.

→ A controlled switch-over with no service disruption, and an industrialised workstation build.

Events & trade shows

Build and hardening of the IT system for a trade-show organiser's subsidiary

Carve-out from the group tenant and migration to a new hybrid Microsoft 365 infrastructure, hardening and reinforcement of security policies, Intune MDM (Corporate and BYOD), rollout of an ITIL-aligned ITSM, securing of the AWS cloud platform (IAM, MFA, WAF), Fortinet firewalls and partner VPNs.

→ An autonomous, secure subsidiary aligned with the group’s standards.

Culture & institutions

Audit and hardening of a museum's Microsoft 365 tenant

Audit of the Microsoft 365 configuration and reinforcement of access through Entra Conditional Access, infrastructure vulnerability assessment, drafting of an audit report and presentation to the IT department and management, prioritised remediation plan.

→ A reduced attack surface and teams made aware of best practice.

Industry

Endpoint security for a food-industry manufacturer

Deployment of a unified tool for managing and securing workstations and servers, industrialisation of the imaging and deployment process for user workstations and factory stations.

→ A consistent, controlled estate deployed at scale.

International group — Publishing & data

Operation and hardening of a critical multi-site IT system

Responsibility for the infrastructure and security of a critical, multi-site information system: operations, evolution projects (network, systems, virtualisation, storage, ToIP), annual security audits conducted with ANSSI-certified partners, compliance with the group’s information security policy, migration of critical applications to AWS and Azure cloud, disaster recovery site.

→ A sensitive information system kept in service continuity and under control.

Public sector

Deployment of a secure administration architecture for a public-sector body

Implementation of a tiered administration model isolating critical resources (Tier 0), with hardened privileged access workstations (PAW), strong authentication (MFA) and mandatory jump-host access through bastions. Segmentation of administration traffic and rigorous management of privileged accounts.

→ A fully compartmentalised administration model, aligned with ANSSI best practice.

Public sector

Securing the mobile fleet of a public-sector organisation

Deployment of a Mobile Threat Defense (MTD) solution providing real-time protection for devices across the three threat vectors — applications, network and system: blocking of malicious or intrusive applications, network attacks and phishing, and monitoring of device integrity and compliance. Integration with fleet management (UEM/MDM) for automated remediation and conditional access, while respecting user privacy and GDPR.

→ A mobile fleet continuously protected against malicious applications, phishing and network attacks, while safeguarding staff privacy.